NT Index Server Remote Registry Vulnerability
BID:476
Info
NT Index Server Remote Registry Vulnerability
| Bugtraq ID: | 476 |
| Class: | Configuration Error |
| CVE: |
CVE-1999-1397 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 23 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | This vulnerability was discovered and posted to bugtraq by David Litchfield <[email protected]> |
| Vulnerable: |
Microsoft Index Server 2.0 |
| Not Vulnerable: | |
Discussion
NT Index Server Remote Registry Vulnerability
During installation of Microsoft Index Server 2.0 a new registry entry is created and added to the list of network-available subkeys. This list is found at: HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedPaths
The added subkey is HKLM\System\CurrentControlset\Control\ContentIndex\Catalogs. What this does is allow an intruder to gather information about the physical structure of paths and sirectories being indexed, and in the case of remote indexing also the machine name and the account used.
During installation of Microsoft Index Server 2.0 a new registry entry is created and added to the list of network-available subkeys. This list is found at: HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedPaths
The added subkey is HKLM\System\CurrentControlset\Control\ContentIndex\Catalogs. What this does is allow an intruder to gather information about the physical structure of paths and sirectories being indexed, and in the case of remote indexing also the machine name and the account used.
Solution / Fix
NT Index Server Remote Registry Vulnerability
Solution:
Remove the new entry in HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedPaths.
Solution:
Remove the new entry in HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\Winreg\AllowedPaths.